Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 21, 2010, 12:21:43 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373456
Posts
41427
Topics
94165
Members
Latest Member:
2Tall
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Firewall
Help for v2
Is this a bug, or something my brain doesn't get?
« previous
next »
Pages:
[
1
]
Author
Topic: Is this a bug, or something my brain doesn't get? (Read 2697 times)
m0ng0d
I used to be indecisive, but now I'm not so sure.
Global Moderator
Comodo's Hero
Offline
Posts: 811
Is this a bug, or something my brain doesn't get?
«
on:
November 12, 2006, 10:22:48 PM »
I wanted to attach the popup, but I miskeyed grabbing it, so the log entry will have to do; please check the screenshot below.
In my screenshot, I have MailWasher (3rd party e-mail spam helper) attempting to go out to my ISP to inspect my e-mail. The highlighted record corresponding to the details section is that attempt, and the log entry below it in the list is the call to the NS to get the IP for my ISP's pop3 server.
Some helpful background.... MailWasher.exe loads with windows on startup (into the systray), and as such, seems to have been assigned the parent of explorer.exe. I have App rules in place to allow mailwasher to do access the web.
So my PC is all freshly booted... I load up Firefox off my QuickBar... and it gets associated to explorer.exe as its parent as well. I do my browsing & decide to check my e-mails with Mailwasher. And no sooner do I press its button to check my e-mails... the suspicious behavior popups start rolling in.
And in this lies my confusion...
How can "Child B" of "Parent A" be considered a threat to "Child A" of "Parent A" when the 2 of them never interact?
Is it that CPF assumes a parent can have only one child?
If I trust the Detail message and block the action, why is it MailWasher that gets blocked? ... I thought it was firefox that was "misbehaving" (according to the details)
Does the Detail message even belong to the activity at hand?
Is there a bug here? Or am I just not understanding something? Which of the 6 things monitored under Application Behavior Analysis does CPF think is going on here?
I'd get similar "collisions" in many applications with services.exe as the parent of svchost.exe (if i remember correctly).
Are there some configuration steps I can take to eliminate these kinds of "collisions", while still maintaining my security?
«
Last Edit: November 12, 2006, 10:54:11 PM by m0ng0d
»
Logged
OS:
Win7 Ultimate x64
Comodo:
CIS 3.14
,
Backup 2.0
,
CSC 2.0
Other Security:
Mailwasher Pro 6.1 LFE
Wish:
x64 iVault for FireFox
panic
Global Moderator
Comodo's Hero
Offline
Posts: 8105
substance constant, depth variable
Re: Is this a bug, or something my brain doesn't get?
«
Reply #1 on:
November 12, 2006, 10:47:47 PM »
Quote from: m0ng0d on November 12, 2006, 10:22:48 PM
How can "Child B" of "Parent A" be considered a threat to "Child A" of "Parent A" when the 2 of them never interact?
Is it that CPF assumes a parent can have only one child?
If I trust the Detail message and block the action, why is it MailWasher that gets blocked? ... I thought it was firefox that was "misbehaving" (according to the details)
Does the Detail message even belong to the activity at hand?
Hey Dan,
1) While A and B don't interact, for this association to be made, there must be a common factor - I smell OLE cooking.
2) CPF correctly acknowledges multiple children for a single parent.
3) MailWasher gets blocked because it is the subject of the rule/condition violation. The details are reporting how the nominated app was being affected. If a wheel falls off the car, the effect is "car don't go" - cause is lack of round bit. CPF, in the case of OLE alerts, looks like it highlights "effect" and details "cause". Sort of vice versa thinking, but I can see their logic (providing I've interpreted it correctly
)
4) Only through the common element - OLE.
Dan, I think you're at the point where you will have to compromise between security and productivity. Glad it's you and not me. LOL
Hope this helps,
Ewen :-)
P.S. If I've got any of this wrong, or if someone else can explain it better, please jump in. I'm married - I'm used to corrections. LOL
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
m0ng0d
I used to be indecisive, but now I'm not so sure.
Global Moderator
Comodo's Hero
Offline
Posts: 811
Re: Is this a bug, or something my brain doesn't get?
«
Reply #2 on:
November 12, 2006, 11:07:10 PM »
Ah... when reading the Application Behavior Analysis list... my brain stopped at "Monitor COM attempts" when it should have read
Monitor COM / OLE Automation attempts
... at least that clears the "what setting" question...
According to the "Comodo_Firewall_2.3_vs_The_Leaktests.pdf", OLE Automation is defined as...
Quote
Windows operating system also provides inter process communication mechanism through COM interfaces. By using a COM interface hosted by a server application, a Trojan can hijack the application to connect to the Internet.
Which was the server application in this experience? The shared parent explorer.exe?
And how was Mailwasher's desire/action to check my e-mail a result of inter process communication from Firefox? I thought I pressed the button.
Logged
OS:
Win7 Ultimate x64
Comodo:
CIS 3.14
,
Backup 2.0
,
CSC 2.0
Other Security:
Mailwasher Pro 6.1 LFE
Wish:
x64 iVault for FireFox
panic
Global Moderator
Comodo's Hero
Offline
Posts: 8105
substance constant, depth variable
Re: Is this a bug, or something my brain doesn't get?
«
Reply #3 on:
November 12, 2006, 11:18:59 PM »
Quote from: m0ng0d on November 12, 2006, 11:07:10 PM
Ah... when reading the Application Behavior Analysis list... my brain stopped at "Monitor COM attempts" when it should have read
Monitor COM / OLE Automation attempts
... at least that clears the "what setting" question...
Which was the server application in this experience? The shared parent explorer.exe?
And how was Mailwasher's desire/action to check my e-mail a result of inter process communication from Firefox? I thought I pressed the button.
Hey Dan,
Please bear in mind that I'm no OLE guru, I only delve into that stuff when I have to - similar to entering a teenagers bedroom - only done under duress, in dire circumstances and usually with a sense of dread! And a gasmask! LOL
My guess is that the server app would be explorer.exe - the windows shell. Objects initialized from the Quick Launch are actually init'd by explorer, as are autostarted apps from startup. There's one link between the two apps before we even get to OLE.
I don't know e3nough to go any further without researching. Did you want me to have a dig around and see what I can come up with?
Cheers,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
m0ng0d
I used to be indecisive, but now I'm not so sure.
Global Moderator
Comodo's Hero
Offline
Posts: 811
Re: Is this a bug, or something my brain doesn't get?
«
Reply #4 on:
November 12, 2006, 11:22:28 PM »
No, this wasn't homework for you ewen
I have no problem waiting for an official response. I know they are busy developing, but I might get lucky!!
Like you said...
Quote from: panic on November 12, 2006, 10:47:47 PM
Dan, I think you're at the point where you will have to compromise between security and productivity. Glad it's you and not me. LOL
... it's just been one of those little things gnawing at me that I finally just had to write the question for.
«
Last Edit: November 12, 2006, 11:24:12 PM by m0ng0d
»
Logged
OS:
Win7 Ultimate x64
Comodo:
CIS 3.14
,
Backup 2.0
,
CSC 2.0
Other Security:
Mailwasher Pro 6.1 LFE
Wish:
x64 iVault for FireFox
m0ng0d
I used to be indecisive, but now I'm not so sure.
Global Moderator
Comodo's Hero
Offline
Posts: 811
Re: Is this a bug, or something my brain doesn't get?
«
Reply #5 on:
November 12, 2006, 11:38:04 PM »
Ah, it seems I am regurgitating what others have already asked... like
comicfan2000
And upon further reading...
Quote from: comicfan2000 on October 19, 2006, 01:56:56 AM
Well, the case is closed. I was told CPF doesn't have the capability to decide what's bad or not even if I am choosing to allow or not so it blocks the whole connection. So for most of us with this issue, it's reboot time or allow OLE. I for one hope for this to be fixed some time as I am testing a lot of software and I simply can't be rebooting every time. Hope for a fix...
Paul
So I guess I'll wait for the "It's fixed" or "It's been enhanced" postings.
Like mentioned by other users... I have gotten pretty good at eyeballing the popup, unchecking the "remember" box, and selecting Allow/Deny on the fly... I just don't think I should have to.
«
Last Edit: November 12, 2006, 11:44:28 PM by m0ng0d
»
Logged
OS:
Win7 Ultimate x64
Comodo:
CIS 3.14
,
Backup 2.0
,
CSC 2.0
Other Security:
Mailwasher Pro 6.1 LFE
Wish:
x64 iVault for FireFox
panic
Global Moderator
Comodo's Hero
Offline
Posts: 8105
substance constant, depth variable
Re: Is this a bug, or something my brain doesn't get?
«
Reply #6 on:
November 12, 2006, 11:47:08 PM »
Quote from: m0ng0d on November 12, 2006, 11:38:04 PM
Ah, it seems I am regurgitating what others have already asked... like
comicfan2000
And upon further reading...
So I guess I'll wait for the "It's fixed" or "It's been enhanced" postings.
Like mentioned by other users... I have gotten pretty good at eyeballing the popup, unchecking the "remember" box, and selecting Allow/Deny on the fly... I just don't think I should have to.
No worries Dan. I'm like you, I leave OLE warnings turned on and just eyeball them. If they look odd, I deny, if they look good, I allow (even if its for an app that I recently closed - I think CPF is not keeping up with OLE connection close calls as quickly as it should.
cheers,
EWen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
comicfan2000
Guest
Re: Is this a bug, or something my brain doesn't get?
«
Reply #7 on:
November 13, 2006, 12:42:25 AM »
Howdy m0ng0d,
I copied my answer to you in my topic and will paste it here, two topics may be better than one
<< Yes, I just wish I had an answer for everyone if this was going to be fixed or not. I haven't heard any definate on it or even a fraction of an answer to be honest. I know for a fact that other firewalls , when a USER denies the OLE, you can still connect to the internet after. This is the one and only irritation I have with CPF. I do feel it's a security risk EG... If I am in the middle of something, I simply allow the darn thing so I don't have to reboot. Another EG...I don't like to allow WMP, I was doing some other online stuff, it pops up, if I wouldn't have allowed it, I would have had lost my ebay page etc...I wasn't too happy having to leave it slide. It will stop your connection dead even if on a web page. The minute you go to move on or refresh you get >Cannot find server. I am patiently waiting for an answer and irritably tolerating this right now but honestly if it doesn't get fixed, with all the software testing, graphics stuff, online stuff I do, I simply couldn't keep doing this with CPF and would have to find another. Cry Sad Cry
Paul Sad >>
Paul
AT EWEN: You hit the teenager's room right on. I have my closet filled with spare gas masks and rubber suits just in case. For the boys bathroom, I call in specialists!
«
Last Edit: November 13, 2006, 12:44:02 AM by comicfan2000
»
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in -0 seconds with 20 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com